Conducting A Risk Assessment - Developing A Security Policy - Technical Risk Analysis - Risk Management Assessment Answer

Download Solution Order New Solution
Conducting A Risk Assessment - Developing A Security Policy - Risk Management Assessment Answer
Assignment Task:

Task

Assignment Two is comprised of two parts which should be addressed as independent reports. In part two you have the option to choose which task you will perform.

Part One - Conducting A Risk Assessment 

You are the Chief Information Security Officer (CISO) at a reputable Australian University. You have been directed by your supervisor to conduct a review of the organisations Digital Security risks, more specifically you have been asked to provide a risk register. The risk register should contain at a minimum:

  • A description of the risk.
  • A summary of the impact or consequence if the risk was to arise.
  • Inherent risk assessment, that is the assessed, raw/ untreated risk inherent in a process or activity without doing anything to reduce the likelihood or consequence.
  • Key controls to mitigate the risk.
  • Residual risk assessment, that is the assessed, risk in a process or activity in terms of likelihood and consequence after controls are applied to mitigate the risk.
  • Prioritisation of the risk using a standardised framework such as the ANSI B11.0.TR3

Risk Assessment Matrix

Given the fact there is no clear prioritisation framework NOR risk appetite framework, the risk register is your professional assessment of the likelihood and consequence of the risks you identify. When preparing your risk register you should think carefully about the assets a University may have and how these may be compromised from the perspective of Information Security.

In the event you are not comfortable conducting a risk assessment on a University, you are free to conduct it on an entity you are affiliated with. If you elect to do this, you need not specify the name of the business, rather provide a summary as to what the entity does.

Your risk assessment table should not be more than 4 pages in length and MUST be accompanied with a covering note outlining the rationale for your assessment and any pertinent points to your argument. Be sure to reference accordingly.

Part Two  

Option One - Developing a Security Policy

Let's imagine you work for the Commonwealth Scientific and Industrial Research Organisation (CSIRO)

Information Technology at CSIRO is controlled by the Division of Information Technology. CSIRO employs a number of administrators to maintain IT resources across the site – this includes production systems which offer services and user workstations. In addition to this CSIRO employs on a full/part-time basis a number of staff to perform operational roles in various units such as Research Operations, HR and Payroll. There is currently 5000 operational staff. Some staff are employed under fixed-term contracts whilst others may be contractors to CSIRO i.e. they own a business and contract to the organization.

That said from time to time people would need Administrator privileges to Enterprise systems or workstations. CSIRO needs the policy to decide who, when and why someone should receive these privileges. By default, everyone is given normal user privileges.

You are employed as the Security Advisor for the organization. The task that is handed to you by the Chief Information Officer now is to write a policy for the granting of privileged accounts to users. When granting privileges such as the administrator account you really need to think of the role and type of employment of the individual. You also need to think about the attributes this individual must possess and the requirements they must have met. How will you implement this? For example if a person from HR wants the administrator account to their desktop computer – what would you do? What if they wanted administrator privileges to a production system? What if a person who is responsible for Information Technology wants administrator accounts to a desktop workstation or production – what would you do, would you always grant them this right?

In your policy you should:

  • define the intent and rationale of the policy
  • any definitions which are used through out the document.
  • responsibilities of individuals i.e. those who enforce the guideline
  • scope of the policy i.e. who and what it effects
  • anything else you think is reasonable to place into a policy based on what you have learnt

You should note that CSIRO has a Chief Information Officer responsible for Information Technology across the site, and an IT security advisor responsible for the formulation of such policies. The IT Security advisor is responsible for enforcing this guideline. The policy covers CSIRO corporate and research assets, its does not cover use facilities such as the PAWSEY Super Computing Centre or corporate subsidiaries of CSIRO. 

Option Two - Recommendations on the Appointment of a CISO

You have recently been appointed as the Chief Information Officer (CIO) of a newly established Pharmaceuticals startup which as part of its business model conducts
research and development into medical products, manufactures medical products and distributes them. The startup has recently been given significant venture capital money with the requirement to improve organisational risk management and governance. 

You have been tasked by the Chief Executive Officer (CEO) to prepare a paper for consideration by the board of directors regarding the need to appoint a Chief Information Security Officer (CISO). The CEO has expressed the view that other members of the board are sceptical about the need to appoint a CISO, in particular
one that operates at the C-Level within the organisation.

Prepare a paper no more than 3 pages outlining your recommendation to the CEO and the Board regarding the appointment of a CISO. Clearly articulate the case for or
against making reference to reporting lines if you believe the appointment is appropriate. In preparing your response to be sure to include referenced examples to substantiate your claims.

This assessment task will assess the following learning outcome/s:

  • be able to justify the goals and various key terms used in risk management and assess IT risk in business terms.
  • be able to apply both quantitative and qualitative risk management approaches and to compare and contrast the advantages of each approach.
  • be able to critically analyse the various approaches for mitigating security risk, including when to use insurance to transfer IT risk.
  • be able to critically evaluate IT security risks in terms of vulnerabilities targeted by hackers and the benefits of using intrusion detection systems, firewalls and vulnerability scanners to reduce risk.

Assessment Item 3 

Task

The assignment involves producing a comprehensive risk report for your organisation given a particular scenario. You will be required to offer professional views based on well-established research.

Technical Risk Analysis

You have been hired by a small IT company to analyse the technology environment and conduct a technical risk analysis. You are to prepare a management report applying everything you learnt in the subject. The report should include at a minimum:

  • An Executive Summary at the beginning of the report which provides a clear statement of the technology project that is being assessed, and an overview of your recommendations to management as to the merits of the project based on your risk assessment.
  • A risk assessment based on assets, threats, vulnerabilities and consequences derived from an IT control framework and any existing industry risk recommendations for the project. Identify and discuss key threats. What could be done to mitigate the risks and their impact on the organisation?
  • Provide a brief summary of the protection mechanisms you would employ whether they be people, culture or technology.  
  • Identify any gaps which you believe require further analysis and offer a rationale as to why.

 

This Risk Management Assignment has been solved by our Risk Management Assignment Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our experts are well trained to follow all marking rubrics & referencing style.

Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.